Field Manual PHP / Laravel reference
← Security

Secrets management

Secrets include credentials, tokens, and encryption keys.

What it is

Secrets include credentials, tokens, and encryption keys.

When to use it

Keep them out of source, responses, and diagnostics.

Syntax

// config/services.php
"bank" => ["key" => env("BANK_API_KEY")],

Example

// .env is excluded from Git.
$key = config("services.bank.key");
// Rotate leaked keys and revoke old access.
// Grant each credential the minimum scope required.

Common mistakes

Removing a secret from the latest commit does not remove history; never publish .env or APP_KEY.

Related topics

Browse Security